A ransomware group calling itself Unsafe posted samples of Deutsche Bank employee data in early July 2026, drawn from a third-party marketing and incentive platform the bank uses. Deutsche Bank confirmed a supplier breach but said “there is no indication that Deutsche Bank’s internal systems or networks were affected.” Researchers who reviewed the leaked screenshots, which include employee emails, password hashes, and addresses, assessed them as appearing legitimate. The incident is a live test of third-party risk rules under the EU’s DORA regulation.
What did the Unsafe group claim?
Unsafe posted screenshots purporting to show Deutsche Bank employee records: corporate email addresses, password hashes, physical addresses, and internal database rows. The group continued releasing samples through the week. Cybernews researchers who examined the material said it appeared legitimate, though they cautioned it was “not possible to determine whether customer data is included.” No specific ransom figure has been made public.
What did Deutsche Bank say?
The bank confirmed a breach at a third-party provider, a marketing and incentive platform, and drew a firm line around its own estate: no indication that internal systems or networks were affected. That is a plausible and common outcome. Enterprises push large volumes of employee and campaign data to SaaS vendors, and a vendor compromise can expose that data without any attacker ever touching the enterprise network. The gap worth watching is between the bank’s confident denial and the researchers’ read that the samples look real.
Why this is a DORA stress test
The EU’s Digital Operational Resilience Act makes financial firms accountable for the ICT risk their third parties carry. A supplier breach exposing employee data is precisely the scenario DORA was written for: the bank’s own controls held, but its vendor’s did not, and the reputational and regulatory exposure still lands on the bank. How Deutsche Bank documents, reports, and remediates this vendor incident is the kind of case that will shape how European regulators read third-party obligations in practice.
What affected employees should do
Any Deutsche Bank employee whose corporate credentials appear in the samples should assume the password hash is compromised and treat the account as needing an immediate reset, ideally with phishing-resistant multi-factor authentication. Password hashes can be cracked offline, so the exposure is not neutralized by the vendor pulling the data. Reused passwords elsewhere should be rotated too, and staff should watch for targeted phishing that uses the leaked internal details for credibility. Track the Ransomtracker live feed for any escalation.
Frequently asked questions
Was Deutsche Bank’s own network hacked?
The bank says no. It confirmed a breach at a third-party marketing and incentive platform and stated there is no indication its internal systems or networks were affected.
Who is the Unsafe ransomware group?
Unsafe is the group that posted the Deutsche Bank employee data samples. It is a lesser-known extortion actor, and details about its wider operations remain limited.
What data was exposed?
The leaked samples include employee emails, password hashes, physical addresses, and internal database records. Researchers could not confirm whether any customer data is included.
Is customer banking data affected?
There is no confirmation that customer data was exposed. The available samples relate to employee and internal platform records, not customer banking systems.
What is DORA and why does it matter here?
DORA is the EU’s Digital Operational Resilience Act, which holds financial firms responsible for the ICT risk carried by their third-party suppliers. A vendor breach like this is exactly the third-party scenario the regulation governs.
